VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,083)

page 14 of 255
  • CVE-2026-13447CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.00

    The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates…

  • CVE-2026-37006CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.

  • CVE-2026-75325CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.

  • CVE-2026-79787CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service…

  • CVE-2026-78168CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.01

    A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit…

  • CVE-2026-77002CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

  • CVE-2026-77001CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any…

  • CVE-2026-77000CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by…

  • CVE-2026-17142CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.

  • CVE-2026-16656CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.

  • CVE-2026-18031CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.

  • CVE-2026-70905CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SAML…

  • CVE-2026-74894CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user…

  • CVE-2026-19924CriAug 16, 2026
    risk 0.64cvss 9.8epss 0.01

    A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-15341CriAug 15, 2026
    risk 0.64cvss 9.8epss 0.01

    The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore executed on every request, performs no nonce,…

  • CVE-2026-15303CriAug 15, 2026
    risk 0.64cvss 9.8epss 0.01

    The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability,…

  • CVE-2026-17182CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.

  • CVE-2026-48528CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.00

    Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints due to unsanitized user input…

  • CVE-2026-14182CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.01

    The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and…

  • CVE-2026-26035CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to…